TriPass Phishing Scanner

Runs on your device · nothing is uploaded

Is that email a phishing attempt?

Paste an email or a link. The scanner reads what the email is actually asking you to do, checks whether that fits who sent it and where its links go, and shows you the reasons. Words like “urgent” or “invoice” on their own are not treated as warning signs.

Check an email or link

Use it inside Outlook

Checks every email you open and shows the verdict at the top of the message. Add it once, open any email, select Scan email, then select the pin icon in the panel. From then on every email you open is checked automatically, in Outlook on the web, Windows and Mac. On iPhone and Android, tap Scan email in an email's menu.

Download Outlook add-in

Outlook on the web or new Outlook

  1. Open any email, then select Apps (or …) → Get Add-ins.
  2. Go to My add-ins → Add a custom add-in → Add from file.
  3. Choose the file you downloaded and confirm.

Classic Outlook (Windows) and Outlook for Mac

  1. Select Get Add-ins on the Home ribbon.
  2. Follow the same steps: My add-ins → Add from file.
  3. Open an email and click Scan email.

Phones and whole organisations

  1. On iPhone and Android, the add-in appears in any email's … menu once you've added it on a computer.
  2. IT admins can deploy it to everyone from the Microsoft 365 admin centre → Integrated apps → upload the file.

Install it as an app

The checker above also installs as an app and works offline.

Windows, Mac, Linux

In Chrome or Edge, click Install app at the top of this page or the install icon in the address bar.

Android

In Chrome, tap ⋮ → Install app.

iPhone and iPad

In Safari, tap Share → Add to Home Screen.

How it works

1. What is it asking?

Each sentence is read to find instructions aimed at you: sign in, pay, change bank details, call a number, install software, buy gift cards, keep it quiet. Advice, news, alerts and “don't do this” sentences are not requests.

2. Does it fit the sender?

Signing in at the sender's own, verified website is normal. Signing in on a look-alike or a free hosting page is not. Inside Outlook the sender's authentication (SPF, DKIM, DMARC) is checked too.

3. Is it avoiding checks?

Secrecy, “I can't take calls”, a free-mail address for a manager or supplier, or a phone number about a charge you didn't make. Pressure such as “within 24 hours” only matters when one of these is present.

Two machine-learning models also run in your browser: one reads the wording, one examines every link (look-alike domains, raw IP addresses, hidden redirects, risky domain endings). The wording model only supports a verdict; it can't flag an authenticated sender on vocabulary alone. No email content ever leaves your device. Everything downloads once with the page and then works offline.